IP Intelligence Briefing: 94.75.225.81
Date: 2026-06-09
---
**1. Risk Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: Tor Exit Nodes (high-risk category)
- Ownership: Leaseweb NL (AS60781), Netherlands.
- Geolocation: Amsterdam, Netherlands (52.13°N, 5.29°E).
- Threat Indicators: No direct malicious activity detected (no blacklists, spam, or campaigns).
---
**2. Network Behavior**
- Tor Exit Node: Confirmed as a Tor exit node (signal ID 6), flagged in 1/8 threat feeds.
- Services: No open ports or TLS certificates detected.
- Routing: BGP prefix 94.75.192.0/18, stable route with no recent changes.
- DNS: No PTR records or domain associations.
---
**3. Temporal Observations**
- Recent Activity (2026-06-09):
- Marked as a Tor exit node (confidence 0.85).
- DNSSEC validation successful.
- No DNSBL listings (2/8 lists).
- Historical Trends: No persistent malicious behavior or ownership changes.
---
**4. Relationships & Subnet**
- Linked Entities:
- Same network: Leaseweb NL (AS60781).
- No correlated IPs or certificates.
- Subnet (94.75.225.81/24):
- 0 abuse density, 0 active/compromised neighbors.
- Subnet classified as "clean."
---
**5. Recommended Actions**
- Firewall Rules:
- Block the IP using:
- `iptables -A INPUT -s 94.75.225.81 -j DROP`
- `nft add rule inet filter input ip saddr 94.75.225.81 drop`
- Cloudflare/WAF rule: `ip.src eq 94.75.225.81`
- Monitoring:
- Watch for Tor-related traffic or connections to this IP.
- Investigate Leaseweb NLโs network for broader risks.
---
**6. Summary**
The IP is a Tor exit node with no direct malicious indicators but poses potential risks due to its association with Tor. While the subnet is clean, the Tor exit classification warrants blocking and monitoring. No immediate action is required beyond defensive measures, but ongoing observation is advised.
SOC Note: Verify if this IP is part of a larger malicious infrastructure or campaign.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | LEASEWEB-NL-MNT |
| ASN | AS60781 |
| Network Name | โ |
| CIDR Block | 94.75.192.0/18 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 56% | 2 | 11 |
| routing | 30% | 2 | 3 |
| services | 34% | 2 | 3 |
| ownership | 40% | 3 | 10 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 36% | 12 | 33 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:51 UTC |
| Last Seen | 2026-06-26 00:33:24 UTC |
| Profile Built | 2026-06-25 21:51:17 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 68 |
Full dossier details are available via our API.